
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-30938 is a security control bypass vulnerability in Parse Server, an open-source Node.js backend platform, affecting the requestKeywordDenylist feature. The vulnerability allows unauthenticated remote attackers to bypass keyword-based input filtering by placing a nested object or array before a prohibited keyword in the request payload. It affects all Parse Server versions prior to 8.6.12 and versions 9.0.0 through 9.5.1-alpha.1. The advisory was published on March 7, 2026, with patches released the same day. It carries a CVSS v4 base score of 6.9 (Medium) and a CVSS v3.1 base score of 5.3 (Medium) (Github Advisory, Parse Server Advisory).
The root cause is a logic bug (CWE-693: Protection Mechanism Failure) in the recursive object scanner used by requestKeywordDenylist. When the scanner encounters the first nested object or array in a request payload, it prematurely stops scanning sibling keys at the same level, meaning any prohibited keyword placed after a nested value is never evaluated. An unauthenticated attacker can exploit this remotely by crafting a JSON request payload that includes a nested object or array before the prohibited keyword, effectively rendering the denylist inoperative for that request. The same bypass technique works against any custom requestKeywordDenylist entries configured by developers. The fix replaces the recursive scanner with an iterative stack-based traversal that fully processes all nested values, and also eliminates a secondary risk of stack overflow on deeply nested payloads (Parse Server Advisory, Github Advisory).
Successful exploitation allows an attacker to submit request payloads containing keywords that are explicitly prohibited by the server's security configuration, resulting in unauthorized data writes or manipulation of backend data. The primary impact is on data integrity — there is no direct confidentiality or availability impact per the CVSS scoring. Because requestKeywordDenylist is enabled by default and all Parse Server deployments are affected, the scope of exposure is broad, potentially allowing attackers to inject dangerous query operators or other prohibited constructs into backend data stores (Parse Server Advisory, Github Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure. The vulnerability requires no authentication, no user interaction, and no special privileges, making it trivially exploitable by any network-accessible attacker against a vulnerable Parse Server instance. The EPSS score is approximately 0.067% (21st percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been identified (Github Advisory).
requestKeywordDenylist (default entries typically include dangerous MongoDB query operators such as $where, $regex, etc.).{
"nested": { "key": "value" },
"$where": "malicious expression"
}POST to /parse/classes/<ClassName>) that would normally reject the prohibited keyword./parse/classes/*) containing JSON payloads with both nested objects/arrays and known prohibited keywords (e.g., $where, $regex, $function) in sibling positions.Parse Server has released patched versions 8.6.12 (for the 8.x branch) and 9.5.1-alpha.1 (for the 9.x branch), both published on March 7, 2026. Upgrading to one of these versions is the recommended remediation. As an interim workaround, administrators can implement a Cloud Code beforeSave trigger to manually validate incoming data for prohibited keywords across all classes, compensating for the bypassed denylist (Parse Server Advisory, Release 8.6.12, Release 9.5.1-alpha.1).
The vulnerability was reported by security researcher 0xkakash1 and coordinated by Parse Server maintainer mtrezza, who published the advisory and patches simultaneously on March 7, 2026. No significant broader media coverage or notable community commentary beyond the official advisory has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."